MSI site analytics pixel

Systemic Failure: 7 Courageous Steps Leaders Must Take Now

ISO 9001:2026 · Leadership Accountability · Recovery

By Diana Lynn, President and Principal ISO Consultant, MSI · Updated October 2, 2026

Systemic failure is a breakdown built into how an organization works, so it repeats no matter who is doing the job. On September 4, 2024, a London public inquiry published roughly 1,700 pages proving how long one can last. It found the Grenfell Tower fire, which killed 72 people, was “the culmination of decades of failure” by government and industry bodies who had the information and did not act on it (Grenfell Tower Inquiry Phase 2 Report ).

Nobody at Grenfell lacked a procedure. That is the signature of a systemic failure. The warnings were on file. Earlier cladding fires were on file. Residents’ complaints were on file. What was missing was a leader willing to read the record, say “this is wrong,” and draw a line nobody was allowed to cross.

Direct Answer: You fix a decades-old systemic failure in seven steps: admit it, read the records as evidence, name the harmed interested parties, deal with the consequences, redirect falsifying third parties, install daily procedures, and decide honestly whether to change or close.

Key takeaways

  • ISO 9001:2026 requires top management to take accountability for the effectiveness of the quality management system (Clause 5.1.1 l).
  • Clause 10.2.1 a) 2) requires the organization to deal with the consequences of a nonconformity, not only correct it.
  • Clause 4.2 requires organizations to determine relevant interested parties and monitor their requirements, which makes harm to them a system issue.
  • Clause 8.4.2 d) requires verification of what external providers deliver, so a falsifying supplier is a control failure, not bad luck.
  • A systemic failure is almost always visible in records years before it becomes a headline.
  • Redemption is earned, not announced: trust returns when stated intentions are proven to interested parties over time.
  • Some organizations cannot change, and an orderly, deliberate closure is more honest than decades of controlled decline.

This article is for the leader who inherits a system that has been going wrong for a long time, and for the people who have watched it happen and kept quiet. It draws on 28 years of ISO consulting at Management Systems International (MSI), across 200+ audits attended, 80+ certifications supported, and 600+ professionals trained in manufacturing, technology, medical device, government, healthcare, and other regulated industries. The goal is a system that works in practice every day, not one that only looks right on paper.


Definition

What Is a Systemic Failure, and Why Does It Survive for Decades?

Repeat. Normalize. Ignore.

A one-time error has a cause you can find and fix. A systemic failure is different: the cause sits in the design of the work, the incentives, or the silence around them. Replace the person and the systemic failure returns, because the system that produced it is still standing.

W. Edwards Deming put a number on this in Out of the Crisis. He estimated that about 94 percent of troubles belong to the system, which he called the responsibility of management, and only about 6 percent come from special causes. That ratio is why blaming the operator, the nurse, or the inspector so rarely ends a systemic failure. It points to the wrong 6 percent.

Systemic failure lasts for decades because each year of tolerance makes the next year easier. Three forces keep it alive:

  • Normalization. A workaround that would have shocked people in year one becomes “how we do it here” by year five. New hires learn the workaround as the procedure.
  • Diffused responsibility. Everyone can see a piece of the problem, but no single role owns the whole. Each department assumes another one is handling it.
  • Punished candor. The first few people who raised it were ignored, moved, or let go. Everyone after them learned the lesson.

MSI’s analysis of dysfunctional company symptoms covers the everyday warning signs. This article goes further, to the point where the failure is decades deep, the records prove it, and leadership has never taken a stand.


Accountability

How Were Leaders Expected to Be Responsible All Along?

Own. Answer. Act.

Leaders who preside over a long systemic failure often say they did not know. The standard has never accepted ignorance of a systemic failure as a reason. Since its first edition in 1987, ISO 9001 has carried a management responsibility requirement, and the 2015 edition already required top management to take accountability for the effectiveness of the quality management system.

ISO published ISO 9001:2026 on September 16, 2026, and it makes the expectation more explicit. Clause 5.1.1 lists twelve ways top management shall demonstrate leadership and commitment. Several read like a checklist of what was missing in every systemic failure discussed here:

  • 5.1.1 c) ensuring the resources needed for the system are available;
  • 5.1.1 e) ensuring the system achieves its intended results;
  • 5.1.1 i) promoting quality culture and ethical behaviour;
  • 5.1.1 l) taking accountability for the effectiveness of the system.

Clause 5.3 f) adds that top management shall assign responsibility and authority for ensuring the integrity of the management system is maintained. Integrity is a named, assigned duty, and its absence is how a systemic failure takes root. If nobody holds it, the organization has already failed a requirement before anything goes wrong on the floor.

NOTE 2 to Clause 5.1.1 states that an organization’s quality culture and ethical behaviour are reflected in its shared values, attitudes, practices, and actions. A NOTE creates no obligation, but it tells you where to look for evidence: at what people actually do. ISO 10010 gives guidance on evaluating and improving quality culture if you need a structured method. MSI’s ISO 9001:2026 executive briefing explains these leadership changes in plain business terms.

The public cases show what this responsibility looks like when it is ignored. At Grenfell, the inquiry assigned failure to bodies “in positions of responsibility”: the people whose job was to act. In the Mid Staffordshire hospital inquiry, chair Robert Francis reviewed evidence from more than 250 witnesses and over a million pages of documents before concluding that a trust focused on targets lost sight of safe care (AHRQ PSNet summary).

“I have always felt that integrity is at the center of all ISO standards.”

— Diana Lynn, President and Principal ISO Consultant, MSI

Responsibility does not stop at the boardroom. Clause 7.3 e) requires people doing work under the organization’s control to be aware of its quality culture and ethical behaviour. That reaches every department, every shift, and every on-site contractor. MSI’s piece on the quality management leadership crisis shows what happens when leaders hand all of this to one quality manager with accountability but no authority.

Direct Answer: Under ISO 9001:2026, top management is responsible for a systemic failure because Clause 5.1.1 l) requires it to take accountability for the system’s effectiveness, Clause 5.1.1 i) requires it to promote quality culture and ethical behaviour, and Clause 5.3 f) requires someone to be assigned to protect the system’s integrity.


Evidence

What Do the Records Already Prove About a Systemic Failure?

Read. Trace. Confirm.

Here is the uncomfortable truth about every long systemic failure: the organization documented it. The systemic failure is in the files. Records rarely lie on purpose. They show the same nonconformity opened and closed nine times, the management review minutes that noted a concern and decided nothing, the supplier certificate nobody checked.

The Grenfell inquiry traced warnings back through earlier cladding fires, beginning with Knowsley Heights in 1991, and found they were not acted on (House of Lords Library). In the peanut contamination case, the U.S. Department of Justice showed that Peanut Corporation of America shipped salmonella-positive product before test results came back and falsified microbiological results (U.S. Department of Justice). According to the 2013 indictment, the disregard for food safety reached back to 2004 (U.S. Senate office summary). The company’s own emails and test records were the evidence.

ISO 9001:2026 makes these records mandatory. Clause 10.2.2 requires documented information as evidence of each nonconformity and the actions taken, and of the results of corrective action. Clause 9.3.3 requires documented information as evidence of the results of management review. Read together, they form a timeline of who knew what, and when.

The Records Reckoning: what to pull in the first two weeks

Use this checklist, built for this article, to turn the archive into evidence. Read each record type for patterns, not individual events, because a systemic failure only shows itself as a pattern.

RecordWhat to look forWhat it proves
Corrective action log (10.2.2)The same cause closed more than twice; actions with no effectiveness checkThe organization treated symptoms and knew it
Management review minutes (9.3.3)Concerns noted with no decision, owner, or dateLeadership saw it and chose not to act
Internal audit reportsRepeat findings across cycles; findings downgraded between draft and finalAssurance was softened before it reached leaders
Complaints and returnsClusters by product, site, or shift that never became a corrective actionInterested parties were telling you
Supplier certificates and evaluations (8.4.1)Certificates accepted without verification; re-evaluations skippedThird-party data was trusted, not checked
Speak-up and concern reportsReports closed without feedback; reporters who later leftCandor was punished or ignored
Deviations and concessionsTemporary approvals renewed for yearsA workaround became the real procedure

MSI’s work on management system oversight shows why this matters beyond the business. When records and management review minutes do not exist, that absence becomes the evidence. Follow-through on findings is its own discipline, covered in MSI’s guide to internal audit follow-up.

Direct Answer: Records almost always prove a systemic failure years before it becomes public: repeat corrective actions, management review minutes without decisions, softened audit findings, and unverified supplier certificates. ISO 9001:2026 Clauses 10.2.2 and 9.3.3 require this evidence to exist, so new leaders should read it first.


Interested Parties

Why Do Affected Interested Parties Change Everything?

Name. Listen. Repair.

A systemic failure is not an internal matter, because its costs land on people outside the organization. Clause 4.2 of ISO 9001:2026 requires the organization to determine its relevant interested parties and their relevant requirements, and to monitor and review that information. Clause 9.3.2 c) brings changes in their needs and expectations into management review.

In a long systemic failure, the interested parties have usually been raising the alarm for years. Grenfell residents warned about fire safety before the fire. After the inquiry, the leader of Kensington and Chelsea Council apologized without reservation for the council’s failure to listen to residents and to protect them (Royal Borough of Kensington and Chelsea). That apology came after 72 deaths. A management system that treats interested parties as a register to fill in, instead of people to hear, is where that failure starts.

When a systemic failure is finally named, list every group it touched and what they are owed:

Interested partyHow a long failure harms themWhat recovery owes them
Customers, patients, residentsUnsafe or nonconforming products and servicesDisclosure, remedy, and proof the cause is gone
EmployeesUnsafe work, moral injury, retaliation for speaking upProtection, a real voice, and a fair process
Contractors and suppliersPressure to cut corners or falsifyClear requirements and a route to raise concerns
Regulators and certification bodiesInaccurate informationTimely, truthful notification
Communities and the environmentReleases, contamination, loss of trustContainment, remediation, and transparency
Owners and governing bodiesHidden exposureAn honest account and a credible plan

Environmental systems follow the same logic. In an EMS, a systemic failure often hides in compliance obligations nobody re-evaluated, and ISO 14001:2026, published April 15, 2026, requires organizations to determine interested parties (Clause 4.2) and their compliance obligations (Clause 6.1.3).

Workers are an interested party with particular weight. MSI’s guides to psychological safety at work and brain drain show how long failures drive out exactly the people who could have fixed them.

Direct Answer: Affected interested parties make a systemic failure a system issue because ISO 9001:2026 Clause 4.2 requires the organization to determine them, understand their requirements, and monitor that information. In most long failures, customers, workers, and communities raised the alarm years earlier and were not heard.


The Method

The 7 Courageous Steps to Rectify a Systemic Failure

Admit. Answer. Rebuild.

These steps are written for a new or newly determined leader. They are in sequence because each one depends on the one before it. You cannot draw credible lines in the sand while still pretending nothing happened.

Step 1: Admit the failure, out loud and in writing

Recovery starts with an admission from the top: this happened, it went on too long, leadership allowed it, and it stops now. Say it to the whole organization, not only the leadership team. Name the system that failed and the period it covered. Do not blame the people who were trapped inside it.

Admission carries legal weight, so have counsel review what must be disclosed externally, to whom, and how. This article is not legal advice. Counsel should shape the wording of an admission. It should never be the reason to avoid one inside the organization.

Step 2: Read the records as evidence, not as history

Run the Records Reckoning above. Assign someone independent of the failed area to do it, and give them protection to report what they find. Map the timeline of the systemic failure: first signal, every later signal, and every decision point where someone could have stopped it.

Step 3: Name every interested party who was harmed

Use the interested party table to list who the systemic failure affected and what each group is owed. Bring the list into management review as an input under Clause 9.3.2 c). Where harm is still occurring, it moves to the top of the plan.

Step 4: Deal with the consequences head on

Clause 10.2.1 a) requires the organization to react to a nonconformity and, as applicable, control and correct it and deal with the consequences. That phrase is a requirement, not a slogan. In a systemic failure, the consequences are large and they do not wait for a convenient time:

  • For the people harmed: remedy, recall, notification, and support. Stop ongoing harm the same day it is identified. Clause 8.7 requires nonconforming outputs to be identified and controlled.
  • For the organization: regulatory notifications, a changed relationship with the certification body, contract losses, and the cost of rework at scale.
  • For the leaders who knew: accountability that matches the role. Some will need to leave. Protecting them signals that nothing has changed.
  • For the system: Clause 10.2.1 b) 3) requires determining whether similar nonconformities exist or could occur elsewhere. A decades-long failure almost always has siblings.

Courts eventually decide consequences when leaders do not. In the peanut case, the former president received a prison sentence of more than a quarter century, and the quality assurance manager and two operations managers were also sentenced (U.S. Department of Justice). Accountability reached every department that touched the falsified records, and the company itself no longer exists.

Facing consequences is not the punishment for a systemic failure. It is the first proof that the system has changed. People inside and outside the organization judge sincerity by what leadership accepts, not by what it announces.

Step 5: Redirect any third party that falsifies

Long failures rarely live inside one organization. Suppliers, laboratories, contractors, and service providers often learned that falsified data would be accepted. New leaders must redirect them immediately. The next section explains how.

Step 6: Draw hard lines with daily procedures

A line in the sand that is announced once and checked yearly is not a line. The systemic failure ran every day, so the replacement has to run every day too. These daily procedures are MSI recommendations, each anchored to a requirement it helps you meet:

Daily lineWhat it looks likeRequirement it serves
Start-of-shift check (15 minutes)Open nonconformities, safety concerns, and overdue actions reviewed with ownersClause 10.2.1; Clause 9.1
Stop authorityAnyone may stop output they believe is unsafe or nonconforming, without penaltyClause 8.7; Clause 5.1.1 f)
24-hour escalationEvery concern reaches a named leader within one working dayClause 7.4; Clause 5.3 b)
Same-day recordsRecords are made when the work is done and never reconstructed laterClause 7.5
Verify at receiptCritical supplier data is independently checked before acceptanceClause 8.4.2 d)
Leader walk with evidenceA senior leader samples one process weekly and records what was foundClause 5.1.1 e) and l)
Monthly recovery reviewManagement review at a shorter planned interval until indicators stabilizeClause 9.3.1; Clause 9.3.3

Write each line as a controlled procedure with a named owner, and verify it is actually running rather than assuming it is. MSI’s guides on continual improvement and ISO 9001 change management explain why event-based fixes fade and system-based ones stick.

Step 7: Decide whether the organization can change, or should close

Some organizations cannot recover. The leadership will is missing, the dishonesty runs too deep, or the harm cannot be stopped while the activity continues. Pretending otherwise prolongs the systemic failure and adds new victims every year it runs.

Mid Staffordshire NHS Foundation Trust was dissolved in 2014, after the public inquiry, and its hospitals were transferred to other providers (The Health Foundation). Peanut Corporation of America no longer operates. In both cases, the end was imposed from outside. The decision matrix below helps leaders make that call deliberately, while they can still protect the people involved. For organizations that choose to recover, the work after the decision is redemption, covered later in this article.

Direct Answer: The seven steps to rectify a systemic failure are: admit it in writing, read the records as evidence, name the harmed interested parties, deal with the consequences under Clause 10.2.1 a), redirect falsifying third parties, replace the bad system with daily procedures, and decide honestly whether to change or close.


External Providers

What Should New Leaders Do When Third Parties Are Falsifying?

Verify. Redirect. Exit.

When a third party is falsifying test results, certificates, inspection records, or reports, the falsification is part of your systemic failure. Clause 8.4.1 of ISO 9001:2026 requires the organization to ensure externally provided processes, products, and services conform to requirements, and to apply criteria for evaluating, selecting, monitoring, and re-evaluating providers.

The Grenfell inquiry found systematic dishonesty by some product manufacturers in how materials were tested and marketed, and lawmakers later described that finding in debate (Hansard, House of Lords). Products were trusted because paperwork said they were safe. Nobody independently confirmed it.

New responsible leaders redirect third parties in this order:

  1. Verify independently. Stop accepting certificates at face value for critical items. Clause 8.4.2 d) requires the organization to determine the verification needed to ensure externally provided products meet requirements.
  2. Contain what is already in the system. Identify and control any output that relied on suspect data, as Clause 8.7 requires.
  3. Put the new line in writing. Clause 8.4.3 requires the organization to communicate its requirements to providers, including the control and monitoring it applies (e) and any verification it intends to perform at their premises (f).
  4. Offer one defined path back. Require a corrective action with evidence, by a date, verified by you.
  5. Re-evaluate and record it. Clause 8.4.1 requires documented information on evaluations and any necessary actions arising from them.
  6. Exit when they refuse. A provider that will not stop falsifying cannot stay in your supply chain. Notify regulators and customers where the law or your contracts require it.
  7. Protect whoever reported it. The person who exposed the falsification needs visible protection, or the next one stays silent.

Redirection also applies to on-site contractors, because Clause 7.3 e) extends culture and ethics awareness to anyone doing work under your control. MSI’s guide to the ISO 9001 ethical supply chain details how certified organizations carry these expectations to suppliers that have never sought certification. For reporting channels, ISO 37002 gives guidelines for whistleblowing management systems, and OSHA publishes recommended practices for anti-retaliation programs.

Direct Answer: When third parties falsify data, it is part of the systemic failure. New leaders should verify independently under Clause 8.4.2 d), contain affected output under Clause 8.7, communicate requirements in writing under Clause 8.4.3, offer one verified corrective path, and end the relationship if the provider refuses.


Original MSI Tool

The Line-in-the-Sand Decision Matrix: Recover, Replace, Reduce, or Close?

Score. Decide. Commit.

MSI built this matrix for this article. It gives leadership a structured, recorded way to make the hardest call in a systemic failure. Score each factor 0, 1, or 2, using the records gathered in Step 2 rather than opinion. Record the scores and the decision in management review minutes.

Factor0 points1 point2 points
Leadership willLeaders deny or minimizeLeaders admit privatelyLeaders admit in writing and accept consequences
Record integrityRecords are falsified or missingRecords exist but are incompleteRecords are complete and trustworthy
Harm statusHarm is ongoing and cannot be stoppedHarm is ongoing but containableHarm is stopped and contained
Third-party honestyKey providers falsify and refuse to changeSome providers falsify but will correctProviders are verified and conforming
Capability to run daily linesNo people or resources to run themPartial capabilityDaily procedures can start this month
Total scoreDecisionWhat it means in practice
8–10RecoverCurrent leadership leads the seven steps with monthly management review.
5–7Replace leadership, then recoverThe system can be saved, but not by the people who presided over it.
3–4Reduce scopeStop the failed process, product line, or site until it can be run under control.
0–2Close deliberatelyPlan an orderly exit that protects customers, workers, and communities.

One override applies regardless of score: if harm to people is ongoing and cannot be stopped within the day, stop the activity first and score afterward. Clause 10.1’s NOTE recognizes that improvement can come through breakthrough change or reorganization. A NOTE creates no obligation, but it confirms that restructuring is a legitimate improvement path.

Closing deliberately is not failure of nerve. It is leadership taking the decision that the systemic failure would otherwise force later, at a worse moment, with more people hurt. Diana’s weekly message to the people who follow her on LinkedIn is the human side of this matrix: if your workplace is healthy, protect it; if it is not, speak up to the right people; and if change truly is impossible, look for work at an organization with a certified management system.

Direct Answer: The Line-in-the-Sand Decision Matrix scores a systemic failure on five factors: leadership will, record integrity, harm status, third-party honesty, and capability. Totals of 8–10 mean recover, 5–7 replace leadership, 3–4 reduce scope, and 0–2 close deliberately, with an override when harm cannot be stopped.


Redemption

How Does an Organization Seek Redemption and Regain Trust After a Systemic Failure?

Intend. Prove. Persist.

Redemption is not a press release. Trust lost over years of systemic failure comes back only through evidence that builds up over years of different behavior. Intention still matters, because people need to know what leadership is trying to repair and for whom. But an intention only counts once it is stated precisely and then proven where others can see it.

Vague intentions such as “we are committed to doing better” sound like the old system talking. Two requirements give redemption a structure. Clause 5.2.2 c) of ISO 9001:2026 requires the quality policy to be available to interested parties, as appropriate. Clause 7.4 requires the organization to determine what it will communicate, when, with whom, and how. Together they let leadership publish its intentions in a form outsiders can check: what will change, by when, and how they will know.

Stated intentionProof that earns trust back
“We will stop the harm.”Containment records, verified by someone independent of the failed area
“We will make it right with those affected.”Remedies actually delivered, and harmed parties consulted on the redesign
“We will tell the truth from now on.”Regular progress reports that include setbacks and missed dates
“Speaking up is safe here.”Reporters visibly protected and every concern closed with feedback
“Leaders are accountable.”Leadership changes and consequences that are visible, not quietly managed
“This will not happen again.”A falling repeat-finding rate, confirmed by external verification

Grenfell shows how long the road is. In February 2025, more than seven years after the fire, the UK government apologized on behalf of the British state and accepted that the inquiry report must drive lasting change (Hansard, House of Lords). Yet the London Assembly had already noted that some recommendations from the inquiry’s first report were still not implemented five years after publication (London Assembly). An apology opens the door to redemption. Only completed actions walk through it.

MSI recommends four principles for leaders seeking redemption after a systemic failure:

  • Promise less and deliver visibly. Every missed commitment costs more trust than the original admission earned.
  • Invite verification. Let independent auditors, and where appropriate the harmed parties themselves, confirm progress rather than asking anyone to take leadership’s word for it.
  • Keep listening. Clause 9.1.2 requires the organization to monitor customer satisfaction, and its NOTE lists sources such as complaints, compliments, meetings with customers, and social media. Use them as a trust gauge, not a scorecard to defend.
  • Never declare victory yourself. Interested parties decide when trust has returned. Leadership’s job is to keep producing the evidence.

Redemption applies inside the organization too. Many employees saw the systemic failure and stayed silent because speaking up was punished. Treat them as part of the recovery, not suspects in it. Leaders can offer a defined window in which people may come forward with information without penalty for past silence. This is an MSI recommendation, and counsel should review its terms. Annex A.5.1 of ISO 9001:2026, which is informative, observes that ethical behaviour can support confidence in the organization’s ability to meet interested parties’ needs. Confidence is the currency redemption is paid in.

Direct Answer: Seeking redemption after a systemic failure means stating specific intentions to interested parties and proving them over time: stop the harm, make it right, report honestly including setbacks, protect those who speak up, and let outsiders verify. ISO 9001:2026 Clauses 5.2.2 c), 7.4, and 9.1.2 give that work a structure.


Requirement Status

What Does ISO Require Versus What MSI Recommends?

Require. Note. Recommend.

Every clause reference below was verified against the licensed text of ISO 9001:2026. A requirement uses “shall.” A NOTE is for consideration only. Annex A is informative and adds no requirements.

ItemSourceStatus
Take accountability for system effectivenessISO 9001:2026 Clause 5.1.1 l)Requirement
Promote quality culture and ethical behaviourClause 5.1.1 i)Requirement
Culture reflected in shared values, attitudes, practices, actionsClause 5.1.1 NOTE 2NOTE
Assign responsibility for maintaining system integrityClause 5.3 f)Requirement
Determine and monitor relevant interested partiesClause 4.2Requirement
Awareness of quality culture and ethical behaviourClause 7.3 e)Requirement
Deal with the consequences of a nonconformityClause 10.2.1 a) 2)Requirement
Check whether similar nonconformities exist elsewhereClause 10.2.1 b) 3)Requirement
Verify externally provided products and servicesClause 8.4.2 d)Requirement
Management review results include decisionsClause 9.3.3Requirement
Quality policy available to interested parties, as appropriateClause 5.2.2 c)Requirement
Determine what, when, with whom, and how to communicateClause 7.4Requirement
Monitor customer satisfactionClause 9.1.2Requirement
Improvement through breakthrough change or reorganizationClause 10.1 NOTENOTE
Ethical behaviour can impact all aspects of qualityAnnex A.5.1Informative
Written admission statement from leadershipNoneMSI recommendation
Published redemption intentions and amnesty windowNoneMSI recommendation
Records Reckoning and Decision MatrixNoneMSI recommendation
Whistleblowing management systemISO 37002Separate guidance standard

For organizations that want compliance obligations managed as a system of their own, ISO 37301 specifies requirements for compliance management systems. Certified organizations moving to the new edition should note the transition dates published by Global ACI: as of October 2026, new certifications are issued only to the 2026 edition from March 31, 2028, and transition must be complete by September 30, 2029. MSI’s free ISO Transition Risk Scorecard and its guide to ISO transition planning help leaders sequence that work.


Management Review

How Does Management Review Become the Court of Record?

Review. Decide. Record.

Every long systemic failure has a trail of management reviews that saw the problem and decided nothing. Clause 9.3.3 now requires review results to include decisions related to improvement opportunities, changes to the system, and resource needs. During recovery, management review becomes the place where admissions, consequences, third-party decisions, and the Decision Matrix score are recorded.

Three changes make the review honest enough to end a systemic failure: each input arrives with an owner, every concern leaves with a decision and a date, and the minutes record dissent instead of smoothing it over. MSI’s guide to auditing quality culture lists the evidence auditors accept, and its article on internal audit mistakes explains why leadership must be audited at every level, not only at the top.


Measurement

How Do You Measure Recovery From a Systemic Failure?

Measure. Show. Sustain.

Recovery that cannot be measured will be declared finished too early. MSI client experience suggests these indicators show whether the system has actually changed:

IndicatorWhat healthy movement looks like
Repeat-finding rateFalling every quarter as root causes are removed
Hours from concern to named leaderConsistently under 24
Share of management review outputs that are decisionsRising toward most items, each with an owner and date
Overdue corrective actionsTrending to zero, with effectiveness checks recorded
Supplier verification discrepanciesVisible at first, then falling as providers correct
Concerns raised and closed with feedbackVolume rises early, which signals trust, then stabilizes
Records created the same dayApproaching all critical records

Expect the numbers to get worse before they get better when a systemic failure is first exposed. When people believe speaking up is safe, hidden problems surface. MSI’s article on how ISO standards help people explains why a rising early count is a sign of health.

Independent verification makes the numbers credible. MSI performs internal audits for organizations that need an outside view, and SureResults carries that discipline forward year round. When senior leadership needs a candid, outside picture of the organization itself, The Portrait is MSI’s diagnostic commissioned from the top. MSI’s list of 200 negative ethics actions and its piece on ISO standards and integrity give teams shared language for what has to stop.

Across 28 years, 200+ audits attended, and 80+ certifications supported, MSI has seen organizations recover from a systemic failure that ran for many years. They share one trait: a leader who stopped explaining the past and started changing the system the same week.

“Having systems, acting on what the records are reporting, and never letting anyone deny the facts is what prevents good systems from deteriorating.”

— Diana Lynn, President and Principal ISO Consultant, MSI


Next Steps

Where Do You Start This Week?

Decide. Document. Deliver.

Ending a systemic failure takes two things leadership cannot supply alone: an honest outside view of where the organization really stands, and independent verification that the new lines hold once the urgency fades.

See what leadership cannot see from the inside

When a failure is decades deep, the people closest to it are often the ones a candid assessment would implicate. The Portrait is MSI’s organizational diagnostic, commissioned by senior leadership, that gives you an independent, unvarnished picture of the organization before you decide whether to recover, replace, reduce, or close.

Explore The Portrait →

Keep the new lines from quietly fading

Systems deteriorate when nobody checks them. SureResults is MSI’s year-round program in which MSI performs your internal audits on an ongoing basis, so the daily procedures, records, and management review decisions from your recovery are verified independently, cycle after cycle.

See how SureResults works →

Not sure which fits? Call MSI at 760-434-9141 and we will talk through where your systemic failure sits and which path makes sense.


FAQ

Frequently Asked Questions About Systemic Failure

Ask. Answer. Act.

What is a systemic failure in a management system?

A systemic failure is a recurring breakdown caused by how work, authority, and incentives are designed, not by one person’s error. It repeats when people change because the system that produces it remains. Fixing it requires leadership to change the system itself.

Who is responsible for a systemic failure under ISO 9001:2026?

Top management. Clause 5.1.1 l) requires it to take accountability for the effectiveness of the quality management system, Clause 5.1.1 i) requires it to promote quality culture and ethical behaviour, and Clause 5.3 f) requires responsibility for system integrity to be assigned.

Should leaders admit a systemic failure publicly?

Leaders should admit a systemic failure plainly inside the organization and in writing, because recovery depends on it. External disclosure should be reviewed by legal counsel for what must be reported, to whom, and how. Counsel should shape the wording, not prevent the admission.

What does “deal with the consequences” mean in ISO 9001 Clause 10.2?

Clause 10.2.1 a) 2) requires the organization, as applicable, to deal with the consequences of a nonconformity. In a systemic failure this means stopping ongoing harm, remedying affected people, notifying where required, and checking whether similar problems exist elsewhere under Clause 10.2.1 b) 3).

What should a new leader do if a supplier is falsifying test results?

Treat it as part of the systemic failure. Verify independently under Clause 8.4.2 d), contain affected output under Clause 8.7, communicate requirements in writing under Clause 8.4.3, require one verified corrective action, record the re-evaluation under Clause 8.4.1, and exit if the supplier refuses.

How does an organization regain trust after a systemic failure?

By stating specific, checkable intentions to interested parties and proving them over time. Publish what will change and by when, deliver remedies, report setbacks honestly, protect people who speak up, and invite independent verification. ISO 9001:2026 Clauses 5.2.2 c), 7.4, and 9.1.2 support this work.

When should an organization close rather than fix a systemic failure?

When leadership will not admit the failure, records are falsified, harm cannot be stopped, key providers refuse to stop falsifying, and there is no capability to run daily controls. MSI’s Line-in-the-Sand Decision Matrix treats a score of 0–2 out of 10 as a signal to plan a deliberate, orderly closure.


References
  1. Grenfell Tower Inquiry: Phase 2 Report, Volume 1 (UK Government, 2024)
  2. Debate on the Grenfell Tower Inquiry Phase 2 Report (House of Commons Library)
  3. Grenfell Tower Inquiry: House of Lords debate (House of Lords Library)
  4. Grenfell Tower Inquiry: Phase 2 Report debate (Hansard, House of Lords, February 27, 2025)
  5. Leader responds to the Grenfell Tower Inquiry phase two report (Royal Borough of Kensington and Chelsea)
  6. Report of the Mid Staffordshire NHS Foundation Trust Public Inquiry (UK Government, 2013)
  7. Report of the Mid Staffordshire NHS Foundation Trust Public Inquiry (AHRQ Patient Safety Network)
  8. Mid Staffordshire public inquiry final report and dissolution (The Health Foundation)
  9. Former Peanut Company Officials Sentenced to Prison (U.S. Department of Justice)
  10. Peanut company executives sentenced (Office of U.S. Senator Amy Klobuchar)
  11. ISO 9001:2026 Quality management systems — Requirements (ISO)
  12. ISO launches ISO 9001:2026 (ISO, September 16, 2026)
  13. ISO 10010:2022 Guidance on organizational quality culture (ISO)
  14. ISO 37002:2021 Whistleblowing management systems — Guidelines (ISO)
  15. ISO 37301:2021 Compliance management systems (ISO)
  16. How to Create an Anti-Retaliation Program (OSHA Whistleblower Protection Program)
  17. Recommended Practices for Anti-Retaliation Programs, OSHA 3905 (OSHA)
  18. Transition requirements for ISO 9001:2026 (Global ACI)
  19. Grenfell Inquiry Phase 2 motion (London Assembly)

This article provides general information about management systems and is not legal advice. Clause references are to ISO 9001:2026 and ISO 14001:2026 as published; status and dates are current as of October 2, 2026.

About Management Systems International (MSI)

Diana Lynn, President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

MSI is veteran-owned and female-owned. Call 760-434-9141 or visit msi-international.com.


Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 15 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply